Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: net: stmmac: dwc-qos: Disable split header for Tegra194 There is a long-standing issue with the Synopsys DWC Ethernet driver for Tegra194 where random system crashes have been observed [0]. The problem occurs when the split header feature is enabled in the stmmac driver. In the bad case, a larger than expected buffer length is received and causes the calculation of the total buffer length to overflow. This results in a very large buffer length that causes the kernel to crash. Why this larger buffer length is received is not clear, however, the feedback from the NVIDIA design team is that the split header feature is not supported for Tegra194. Therefore, disable split header support for Tegra194 to prevent these random crashes from occurring. [0] https://lore.kernel.org/linux-tegra/[email protected]/
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 5.4, < 5.4.207 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/029c1c2059e9c4b38f97a06204cdecd10cfbeb8aPatch
- https://git.kernel.org/stable/c/2968830c9b47ce093237483c6207c61065712386Patch
- https://git.kernel.org/stable/c/9cc8edc571b871d974b3289868553f9ce544aba6Patch
- https://git.kernel.org/stable/c/cfa4caf3e881ad6dd366c903c34f1c7f21b857abPatch
- https://git.kernel.org/stable/c/d5c315a787652c35045044877a249f7d5c8a4104Patch
FAQ
What is CVE-2022-49642?
CVE-2022-49642 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: net: stmmac: dwc-qos: Disable split header for Tegra194 There is a long-standing issue with the Synopsys DWC Ethernet driver for T...
How severe is CVE-2022-49642?
CVE-2022-49642 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-49642?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.